Hacker News new | ask | show | jobs
by replete 191 days ago
A whitelist in package.json is only a partial assist